What happened
In June 2021 attackers stole roughly 780GB of data from Electronic Arts, including source code for FIFA 21 and the Frostbite game engine. The intruders told Motherboard they bought stolen authentication cookies for about $10, used them to enter EA's Slack workspace, then messaged EA IT support claiming to have lost their phone at a party and asking for a new multifactor token. The request was granted twice, giving them corporate network access.
How the deception worked
The chain began with a cookie sold on a criminal marketplace that carried a live Slack session for an EA employee. Inside Slack the attackers had the informal context, names and internal jargon needed to sound like staff. They then approached IT support in chat, claiming a lost phone, and persuaded the agent to issue a replacement MFA token without independent identity proofing. With working corporate credentials and MFA they reached EA's internal developer compilation service, created a virtual machine to gain broader network visibility, and downloaded game source code and internal tooling. EA said no player data was accessed.
AI involvement · No AI reported
No AI element reported.
The control that would have caught it· our reading, not a claim from the sources
Help desk MFA resets need identity proofing that does not depend on the requester's own chat account, such as manager verification or a video check against an HR photo record.
Sources (3)
- How Hackers Used Slack to Break into EA GamesVice / Motherboard·vice.comOpen ↗
- Hackers reportedly used EA Games' Slack to breach network, access source codeCyberScoop·cyberscoop.comOpen ↗
- Details Emerge on How Gaming Giant EA Was HackedDark Reading·darkreading.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.